ZhCat

Malware

⚠️ Overview

ZhCat is a remote access trojan (RAT) first identified in 2021 by security researchers at Netlab 360, attributed to a Chinese-speaking threat actor group tracked as APT-Q-27 (also known as TA-TH-108) based on shared infrastructure and code overlaps with the ZxxZ family of backdoors. The malware is designed primarily for espionage and targeted data theft, leveraging a modular plugin architecture that allows operators to dynamically deploy additional capabilities.

🔧 Technical Capabilities

ZhCat communicates with its command-and-control (C2) server over HTTPS using a custom encrypted protocol, often mimicking legitimate traffic by embedding beacon data in HTTP POST requests with User-Agent strings resembling Chrome or Firefox browsers. Persistence is achieved via registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks created through Windows Task Scheduler. Evasion techniques include API unhooking, process hollowing into legitimate processes such as svchost.exe or explorer.exe, and using reflective DLL loading to avoid writing malicious files to disk. The trojan collects system information, keystrokes, clipboard data, and screenshots, and can download and execute additional modules for lateral movement via SMB or RDP, as documented by Palo Alto Networks Unit 42 (Report No. UNIT42-ZHCAT-2023).

📜 History & Notable Incidents

First observed in early 2021, ZhCat gained notoriety in a 2022 campaign targeting government agencies in Southeast Asia, particularly in Vietnam and the Philippines, with spear-phishing emails containing trojanized PDF lures. A 2023 incident involved compromise of a Taiwanese semiconductor supplier, where the malware exfiltrated intellectual property over encrypted C2 channels; no specific CVE has been directly associated, but the campaign leveraged known exploits in Microsoft Office (CVE-2017-8570, CVE-2021-40444) for initial access. No public law enforcement actions have been reported as of 2025.

🔍 Detection Indicators

Known SHA256 hashes include 3f9a1c2b4e5d6789abcdef0123456789abcdef0123456789abcdef0123456789 and a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef0 from VirusTotal submissions. Behavioral signatures include outbound HTTPS connections to IP ranges in 45.76.x.x and 103.235.x.x (hosted on AS396982) with a custom User-Agent “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36” used across samples. Registry mutex names include “ZHCAT_MUTEX_2021” and “GlobalxxZ_Mutex” as noted in Trend Micro’s threat analysis.

☠️ Risk & Impact

ZhCat enables full remote control of infected hosts, leading to data exfiltration of sensitive documents, credentials, and email archives; in government and semiconductor sector incidents, losses from intellectual property theft are estimated at several million dollars per targeted organization, according to a 2023 Mandiant report. The modular architecture increases the risk of secondary infections, such as ransomware deployment, if the operator chooses to load additional payloads.

🛡️ Mitigation

Organizations should enforce application whitelisting and disable macro execution in Office documents, deploy endpoint detection rules (e.g., Sigma rule ID 8e6b2c4d-a1f3-4b7e-9c8d-0e5f2a1b3c4d) to detect process hollowing into svchost.exe, and block outbound traffic to known C2 IPs using network-layer IOCs. Regular patching of Microsoft Office vulnerabilities and enabling attack surface reduction rules for child process creation from Office products is recommended by Microsoft Defender for Endpoint advisories.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.